How to verify an ISO or social compliance certificate in India: a practical checklist for manufacturers and exporters
How to Verify Certificate Details for an ISO or Social Compliance Certificate in India: A Practical Checklist for Manufacturers and Exporters
Before you onboard any new supplier, always verify certificate authenticity and verify certificate details independently, an assumption about a polished document can be a costly mistake. An Indian textile exporter onboarded a fabric supplier who presented an ISO 9001 certificate that looked entirely official. Months later, a buyer audit revealed that the certificate had been issued by a body with no legitimate accreditation, and the scope did not cover the production unit being used. The order was cancelled. The exporter absorbed the cost of re-qualification, damaged buyer relationships, and months of disrupted supply. This is not a worst-case hypothetical. Industry practitioners and accreditation bodies such as NABCB and the IAF have documented repeated instances of forged and misrepresented certificates across Indian manufacturing and export supply chains, making this a recognised, systemic risk rather than an isolated incident.
The fix is not complicated. To verify certificate details correctly, Knowing exactly which fields to read, which registries to check, and which warning signs to look for allows experienced staff to complete a certificate validation efficiently, often in a single working session. At DLV ESG Consulting Group LLP, pre-onboarding certificate checks are a standard part of the supplier due diligence work the team does for clients in manufacturing, textiles, and FMCG. The steps in this article reflect what that process actually looks like, stripped of jargon and presented as a practical checklist you can use right now.
Why skipping certificate verification is a costly mistake for Indian exporters
To verify certificate authenticity before onboarding, exporters should treat every supplier document as a claim that needs independent validation.
ISO and social compliance certificates are increasingly forged or misrepresented in Indian supply chains. Some certificates are genuine documents issued by non-accredited certifying bodies, which makes them commercially worthless to an international buyer. Others are authentic certificates that apply to a different facility, a different product scope, or a certification period that has already expired. In every case, the downstream exporter carries the reputational and financial risk when a buyer audit exposes the gap.
Large international retailers, brand owners, and third-party auditors conducting supplier due diligence do not take certificates at face value. Their auditors verify the certifying body's accreditation status, confirm the certificate number against a public registry, and check that the stated scope actually covers the facility and product line being sourced. If your supplier's certificate fails any of these checks during a buyer audit, the non-conformance reflects on your supply chain management, not just the supplier's documentation quality.
The financial consequences of a failed audit, cancelled orders, re-qualification fees, and emergency corrective action, can be significant, potentially running into several lakhs for a single sourcing relationship depending on the buyer, the sector, and the severity of the gap. A verification check before onboarding costs nothing by comparison. The maths is straightforward.
Five fields to read on every compliance certificate
Before touching any registry or scanning any QR code, verify certificate information by reading the physical certificate carefully. Five fields carry the most critical information, and missing any one of them creates a gap in your verification.
Certificate number and validity dates
Certificate number and validity dates. Every legitimate ISO or social compliance certificate carries a unique certificate number. Write it down first, because this is what you will enter when you verify certificate records in online registries for certificate lookup and cross-checking. The expiry date is equally important. A certificate that expired six months ago is not valid, regardless of whether the holder claims a renewal is "in progress." Confirm the current status independently through the relevant registry so you can verify certificate validity.
Certifying body and accreditation body
Certifying body and accreditation body. The certifying body (CB) is the organisation that conducted the audit and issued the certificate, such as Bureau Veritas, TÜV SÜD, or Intertek. The accreditation body is the entity that authorises the CB to issue certificates in the first place. In India, that is typically the National Accreditation Board for Certification Bodies (NABCB). Internationally recognised accreditation bodies include UKAS (UK), DAkkS (Germany), and ANAB (USA). Both names must appear on the certificate, normally as a printed reference or an accreditation mark. This is essential when you verify certificate authenticity. If the accreditation body is absent or unfamiliar, treat it as an immediate cause for concern and investigate before proceeding.
Scope of certification
Scope of certification. The scope field defines exactly what the certificate covers: which facility address, which processes, and which products or services. A supplier may hold a valid ISO 14001 certificate, but if the scope excludes the production unit that is supplying you, the certificate is irrelevant to your transaction. Read the scope carefully and confirm it matches the specific facility and activity you are sourcing from before you verify certificate relevance. Vague scope statements such as "all manufacturing activities" without a site address are themselves a warning sign.
How to verify a certificate using official online registries
Once you have the certificate number and the CB name, the next step is to verify certificate records by cross-checking against official registries. This is where you confirm that what is printed on the certificate is real and current.
IAF CertSearch for ISO certificates
IAF CertSearch for ISO certificates. To verify certificate details online, use IAF CertSearch, a publicly accessible global certificate registry operated by the International Accreditation Forum. Enter the certificate number or the organisation name to retrieve the full certificate record. The result shows the CB name, accreditation body, scope, issue date, expiry date, and current status. This is the primary online verification tool for ISO 9001, ISO 14001, ISO 45001, and ISO 50001. If a certificate does not appear in IAF CertSearch, you should not assume it is genuine; investigate the CB's accreditation before you verify certificate status.
NABCB directory for India-accredited certifying bodies
NABCB directory for India-accredited certifying bodies. The National Accreditation Board for Certification Bodies maintains a searchable directory of all CBs it has accredited, searchable by CB name, accreditation scheme, and standard. If a certificate claims NABCB accreditation, cross-check the CB's name in this directory. A legitimate CB accredited by NABCB will appear by name, along with the standards it is authorised to certify against. If the CB does not appear, do not rely on the accreditation claim; verify certificate authenticity with the relevant accreditation body.
Sedex and SAI registries for social compliance
Sedex and SAI registries for social compliance. SMETA audits are linked to the Sedex platform. A supplier with a valid SMETA audit will hold an active Sedex membership, and the linked audit report will be visible to connected buyers through the platform. Buyers need to be connected to the supplier through the Sedex relationships function to access the report directly. For SA 8000 certificates, Social Accountability International maintains a searchable registry of certified facilities on its website. Enter the facility name and country to confirm whether the certificate is current and in good standing.
When a certificate is new or niche and does not appear in a registry immediately, email the CB directly with the certificate number and request written confirmation. This gives you another way to verify certificate authenticity. Response times vary by CB, but a prompt, clear written response is a reasonable expectation from a legitimate certifying body. A vague, delayed, or absent response is itself an indicator of risk that warrants further investigation.
QR codes and verification URLs: what they confirm and what they don't
Many modern compliance certificates include a QR code or a printed verification URL, both of which can help you verify certificate details. Scanning the QR code opens a page on the CB's or platform's own server, which fetches the certificate record using a unique token embedded in the URL and displays live details: holder name, scope, issue date, expiry, and current status. This is a real-time database query, not a static display.
A trustworthy verification result appears on a page hosted on the certifying body's own domain, and the details it returns must match exactly what is printed on the physical certificate. If the QR code opens a generic website, a page hosted on an unrelated domain, or simply displays a static image of the certificate, that is not genuine verification. The page must retrieve a live record from the issuer's own database to be meaningful when you verify certificate status.
When you verify certificate details on a mobile device, check the domain shown in the browser address bar before reading the result. If the domain does not clearly belong to the CB or an established credential platform, treat the result with scepticism. A verification link that resolves to a free hosting site, a recently registered domain, or a domain unrelated to the CB's known web address is a strong indicator of a forged document.
Older certificates issued before QR verification became standard practice may carry no QR code at all. Many CBs began integrating QR-based certificate validation progressively from the mid-2010s onwards, so older documents from suppliers in less-audited sectors may predate this. The absence of a QR code is not suspicious on its own, but it does mean you must fall back to the registry lookup steps. Never accept the absence of a QR code as a reason to skip verification entirely; verify certificate information through the appropriate registry instead.
Red flags that signal a forged or invalid certificate
Visual inspection alone is not sufficient to verify certificate authenticity, but it does catch a significant proportion of forgeries before you even reach a registry. According to guidance from NABCB and the IAF, forged certificates typically show a cluster of the following warning signs rather than a single isolated issue.
Visual and structural problems to look for
Visual and structural problems to look for:
Blurry, pixelated, or distorted logos and accreditation marks
Inconsistent fonts, uneven spacing, or abrupt formatting changes between sections
Signatures that appear flat, photocopied, or digitally pasted rather than applied naturally
Certificate numbers that are shorter, longer, or formatted differently from other certificates issued by the same CB
The ISO logo appearing on the certificate itself, which is a widely recognised misuse and a strong authenticity warning
Content inconsistencies worth examining
Content inconsistencies worth examining. The facility address on the certificate must match the actual supplier location in your records before you verify certificate scope. A mismatch between these two addresses requires immediate clarification. Scope statements that are unusually broad or vague, without specifying a site address or a product line, are also a recurring concern in forged or misrepresented certificates. Legitimate CBs use precise, auditable scope language.
Domain and URL mismatches. When a certificate includes a verification URL, paste it into your browser and examine the domain carefully. The domain must belong to the CB or its official platform before you verify certificate details from the URL. If it resolves to an unrelated site or a domain registered recently with no CB branding, the document is almost certainly forged. Legitimate CBs maintain stable, branded domains for their certificate portals and do not change them frequently.
How DLV ESG Consulting Group LLP handles pre-onboarding certificate checks
At DLV ESG Consulting Group LLP, pre-onboarding certificate verification is a structured process designed to verify certificate authenticity, not a quick glance at a PDF attachment. For each supplier certificate, the team cross-checks the certificate number on IAF CertSearch and the NABCB directory to verify certificate records, confirms the scope against the sourcing agreement, and traces the accreditation chain from the CB up to the international accreditation body. Social compliance certificates such as SMETA and SA 8000 are additionally verified against the Sedex platform and the SAI registry respectively.
For manufacturers and exporters managing multiple suppliers, DLV ESG offers structured supplier due diligence packages that help verify certificate authenticity that cover certificate authenticity checks, scope reviews, and accreditation validation across an entire supplier base. Clients in the textile and FMCG sectors have used this service to strengthen their approved vendor lists ahead of international buyer audits, reducing non-conformance risk before it appears in an audit finding.
When a supplier's certificate raises doubts, verify certificate details again and a registry lookup does not resolve them clearly, obtaining a professional review before completing onboarding is the right move. DLV ESG has handled cases where certificates appeared visually credible but failed registry and accreditation checks entirely. In each instance, early detection protected the client from a significantly larger compliance problem. If you are onboarding a new supplier and the certificate verification is raising questions, get in touch with the DLV ESG Consulting Group LLP team before completing supplier onboarding.
Verify Certificate: Quick Supplier Checklist
If your team needs a simple process to verify certificate documents before supplier onboarding, use this checklist:
Verify certificate number against the relevant official registry.
Verify certificate validity by checking the issue and expiry dates.
Verify certificate scope against the actual supplier facility and activities.
Verify certificate accreditation by checking the certifying body's accreditation status.
Verify certificate holder name against the supplier's legal and trading details.
Verify certificate address against the production or operating location.
Verify certificate QR code only through the certifying body's official domain.
Verify certificate status rather than relying only on a PDF supplied by the vendor.
Verify certificate issuer and confirm that the issuer is authorised for the relevant standard.
Verify certificate records again if any detail on the document does not match your supplier information.
The goal is not simply to verify certificate appearance. The goal is to verify certificate authenticity, verify certificate scope, and verify certificate status using independent evidence. A consistent process helps procurement and compliance teams verify certificate information before an international buyer audit exposes a problem.
Verify before you onboard, not after the audit
Verifying a compliance certificate is a practical risk control step, not a bureaucratic formality. The checklist is clear: verify certificate number, verify certificate validity, verify certificate scope, verify certificate accreditation, and verify certificate status. read the five key fields on the certificate, run the certificate number through IAF CertSearch or the relevant social compliance registry, confirm the CB's accreditation in the NABCB directory, scan the QR code and verify the domain, and check for the visual and structural warning signs that indicate a forged or misrepresented document. For detailed guidance on each of these steps, IAF, NABCB, Sedex, and SAI publish publicly accessible how-to resources on their respective platforms.
For manufacturers and exporters managing growing supplier networks, applying this discipline consistently across every new onboarding is where it matters most. A single missed verification can unravel months of supply chain development. That consistency is also where a structured due diligence process, or an experienced specialist partner, delivers measurable improvements to audit outcomes.
The time you invest in certificate authenticity checks before onboarding a supplier is the most efficient compliance investment in your supply chain toolkit. The cost of skipping it is almost always higher than the cost of the problem it would have caught. Do it before the buyer audit forces your hand, and verify certificate details every time a new supplier is onboarded.